- You make a note that this data is being logged.
- You state for how long this is logged (6 months is reasonable), and justify that time frame.
- You state who else has access to these logs.
- You state what steps you have taken to try to minimize unauthorized access to these logs.
- In a register (these statements should be delivered on request of a law supervisor) you also provide your personal details, which users are affected by this data processing, and your goal (which should be something along the lines of: "fraud prevention and intrusion mitigation" to have legitimate interest. Expect big companies with law firms to push this "security interest"-angle hard, as they try to justify their data processing).
Pretty reasonable, no? It would be nice if the large web logging softwares provide standard options to automatically limit disclosure of PII web logs.
I run a small UK based IT firm. So far I've turned down some of the logging on my HA Proxy instances and stopped logging IPs and user agents in general and a few other things. If I need to do some diags then I'll turn them on again. That's on the long term stored logs (due to backups). So far, my backups are smaller 8)
I do keep very detailed logs with IPs (actually full packet capture) in the ES cluster for IDS purposes but those are turned over (deleted) within a few hours. Less detailed logs last a lot longer.
Or, maybe, just block all of the EU.... probably a lot easier for a small site.